΢ÈíSMBv3ºÍ̸Զ³Ì´úÂëÖ´Ðзì϶½¨¸´½¨Òé

°ä²¼¹¦·ò 2020-03-14

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2020-0796£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Windows 10 Version 1903 for 32-bit Systems

Windows 10 Version 1903 for x64-based Systems

Windows 10 Version 1903 for ARM64-based Systems

Windows Server, version 1903 (Server Core installation)

Windows 10 Version 1909 for 32-bit Systems

Windows 10 Version 1909 for x64-based Systems

Windows 10 Version 1909 for ARM64-based Systems

Windows Server, version 1909 (Server Core installation)


·ì϶¸ÅÊö


3ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬Î¢Èí¸üа²È«¹«¸æÕë¶ÔWindows SMBv3¿Í»§¶Ë/·þÎñÆ÷Ô¶³Ì´úÂëÖ´Ðзì϶´¹Î£°ä²¼Á˰²È«²¹¶¡£¬£¬£¬£¬£¬£¬È·¶¨¸Ã·ì϶±àºÅΪCVE-2020-0796¡£¡£ ¡£¡£¡£¡£¡£


Microsoft Server Message Block 3.1.1(SMBv3)ºÍ̸ÔÚ´¦ÖÃijЩҪÇóµÄ·½Ê½ÖдæÔÚ´úÂëÖ´Ðзì϶¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»¾«ÐÄ»ú¹ØÊý¾Ý°ü·¢Ë͵½SMB·þÎñÆ÷£¬£¬£¬£¬£¬£¬ÎÞÐè¾­¹ýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬¼´¿ÉÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý²¿Êðһ̨¶ñÒâSMB v3·þÎñÆ÷£¬£¬£¬£¬£¬£¬²¢ÓÕµ¼Óû§£¨¿Í»§¶Ë£©Ïνӵ½¸Ã·þÎñÆ÷£¬£¬£¬£¬£¬£¬Ò»µ©Ö¸±êÓû§ÏνÓ£¬£¬£¬£¬£¬£¬¼´¿ÉÔÚÍÆËã»úÉÏÖ´Ðй¥»÷Õß×Ô½ç˵µÄ¶ñÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£


ÓÉÓÚÉÏÊö·ì϶Ò×±»È䳿ÀûÓô«²¼¶ñÒⷨʽ£¬£¬£¬£¬£¬£¬´§Ä¦¿ÉÄÜÔÚ½«À´»á³ÉΪ¶ñÒâÈí¼þºÍ¹¥»÷Õß¿í·ºÀûÓõķì϶£¬£¬£¬£¬£¬£¬Óë2017Äê5Ô¡°ÓÀºãÖ®À¶¡±·ì϶½ÏΪÀàËÆ¡£¡£ ¡£¡£¡£¡£¡£


·ì϶¼ì²â


1. ϵͳ°æ±¾¼ì²â


²é¿´×Ô¼ºÊ¹ÓõÄWindows°æ±¾ÊÇ·ñΪÊÜÓ°ÏìµÄ°æ±¾£¬£¬£¬£¬£¬£¬²½ÖèÈçÏ£º


ʹÓÃWin + RºóÊäÈë¡°WinVer¡±²é¿´µ±Ç°²Ù×÷ϵͳµÄ°æ±¾ºÅ¡£¡£ ¡£¡£¡£¡£¡£ÈôÊǰ汾ºÅÏÔʾΪ1903»ò1909£¬£¬£¬£¬£¬£¬ÔòÖ¤Ã÷ÊÜ´Ë·ì϶ӰÏ죬£¬£¬£¬£¬£¬½¨ÒéÁ¢¼´×°Öò¹¶¡¡£¡£ ¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2. ²¹¶¡¼ì²â


ÔÚÊÜÓ°ÏìÁìÓòÄڵIJÙ×÷ϵͳÖУ¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐÒÔϺÅÁî²é¿´²¹¶¡×°ÖõÄÇé¿ö¡£¡£ ¡£¡£¡£¡£¡£


systeminfo | findstr KB4551762

ºÅÁîÖ´ÐÐʵÏÖºóÈôÊÇûÓвéÎʵ½KB4551762²¹¶¡£¬£¬£¬£¬£¬£¬Ôò¸Ãϵͳ´æÔÚ°²È«·çÏÕ¡£¡£ ¡£¡£¡£¡£¡£


3. ¹¤¾ß¼ì²â


´Ë·ì϶ÔÚÍøÉÏÒÑÓй«¿ªµÄ¼ì²â¹¤¾ß£¬£¬£¬£¬£¬£¬¾­ÑéÖ¤ÏÂÁо籾¿É¶ÔSMB°æ±¾½øÐмì²â£¬£¬£¬£¬£¬£¬ÓйØÓû§

¿É×ÔÐÐÑ¡ÔñÏÂÔØÊ¹Óᣡ£ ¡£¡£¡£¡£¡£


Python¼ì²â¾ç±¾

ÏÂÔØÁ´½Ó£ºhttps://github.com/ollypwn/SMBGhost/blob/master/scanner.py


Nmap¼ì²â¾ç±¾(nse¾ç±¾)

ÏÂÔØÁ´½Ó£ºhttps://github.com/cyberstruggle/DeltaGroup/blob/master/CVE-2020-0796/CVE-2020-0796.nse


Powershell¼ì²â¾ç±¾

ÏÂÔØÁ´½Ó£ºhttps://github.com/T13nn3s/CVE-2020-0976/blob/master/CVE-2020-0796-Smbv3-checker.ps1


4. ²úÆ·¼ì²â


8827Ì«Ñô¼¯ÍÅÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·ÒѾ߱¸¶Ô´Ë·ì϶£¨CVE-2020-0796£©µÄɨÃè¼ì²âÄÜÁ¦£¬£¬£¬£¬£¬£¬6070°æ±¾Éý¼¶°üΪ607000278£¬£¬£¬£¬£¬£¬Éý¼¶°üÏÂÔØµØÖ·£º/article/type/1/146.html¡£¡£ ¡£¡£¡£¡£¡£


½¨¸´½¨Òé


΢Èí¹Ù·½ÒÑÕë¶Ô¸Ã·ì϶°ä²¼Á˰²È«²¹¶¡KB4551762£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¿ªÆôϵͳ×Ô¶¯¸üÐÂ×°Öøò¹¶¡½øÐзÀ»¤¡£¡£ ¡£¡£¡£¡£¡£


×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÍÆËã»ú»·¾³ÎÊÌâµÈÔ­Òò£¬£¬£¬£¬£¬£¬Windows UpdateµÄ²¹¶¡¸üпÉÄܳöÏÖʧ°Ü¡£¡£ ¡£¡£¡£¡£¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬£¬£¬£¬£¬£¬Ó¦ÊµÊ±²é³­²¹¶¡ÊÇ·ñ³É¹¦¸üС£¡£ ¡£¡£¡£¡£¡£ÓÒ¼üµã»÷×ÀÃæ×óϽǵÄWindowsͼ±ê£¬£¬£¬£¬£¬£¬Ñ¡Ôñ¡°ÉèÖÃ(N)¡±£¬£¬£¬£¬£¬£¬Ñ¡Ôñ¡°¸üкͰ²È«¡±-¡°Windows¸üС±£¬£¬£¬£¬£¬£¬²é¿´¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬£¬£¬£¬£¬£¬Ò²¿Éµã»÷¡°²é¿´¸üк¹Çà¼Í¼¡±²é¿´º¹Çà¸üÐÂÇé¿ö£¬£¬£¬£¬£¬£¬È·ÈÏÆäÖÐÊÇ·ñÔ̺¬¡°KB4551762¡±

Èô³öÏÖδ³É¹¦×°Öøüв¹¶¡µÄÇé¿ö£¬£¬£¬£¬£¬£¬¿É´Ó¹ÙÍøÏÂÔØÀëÏß×°Öðü½øÐиüУ¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½ÓÈçÏ£º

https://www.catalog.update.microsoft.com/Search.aspx?q=KB4551762


»º½â´ëÊ©£º


1£® ½ûÓÃSMBv3ѹËõ

²½ÖèÒ»£ºÊ¹ÓÃÒÔÏÂPowerShellºÅÁî½ûÓÃѹËõÖ°ÄÜ£¬£¬£¬£¬£¬£¬ÒÔ×èֹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃSMBv3 ·þÎñÆ÷µÄ·ì϶¡£¡£ ¡£¡£¡£¡£¡£

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force


Óû§¿Éͨ¹ýÒÔÏÂPowerShellºÅÁî³·Ïú½ûÓÃѹËõÖ°ÄÜ

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 0 -Force


²½Öè¶þ£ºÓÒ¼üµã»÷×ÀÃæ×óϽǵÄWindowsͼ±ê£¬£¬£¬£¬£¬£¬ÔÚµ¯³ö²Ëµ¥µ±Ñ¡Ôñ¡°ÔËÐÓ×±²Ëµ¥Ï£¬£¬£¬£¬£¬ÔÚµ¯³öµÄÔËÐпòÖÐÊäÈëregedit£¬£¬£¬£¬£¬£¬´ò¿ª×¢²á±í±à×ëÆ÷¡£¡£ ¡£¡£¡£¡£¡£


ÔÚ ¡°HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters¡±Ä¿Â¼ÖÐÔö³¤Ò»¸öDWORDÀàÐ͵Ä×¢²á±íÏîDisableCompression £¬£¬£¬£¬£¬£¬ÊýֵΪ1¡£¡£ ¡£¡£¡£¡£¡£

ÈçÐè³·Ïú½ûÓÃSMBv3ѹËõÖ°ÄÜ£¬£¬£¬£¬£¬£¬½«¸Ã×¢²á±íÏîÊýÖµÅú¸ÄΪ0»òɾ³ý×¢²á±íÏî¼´¿É¡£¡£ ¡£¡£¡£¡£¡£


×¢£ºÀûÓÃÒÔÉϲ½Öè½øÐиü¸Äºó£¬£¬£¬£¬£¬£¬ÎÞÐè³ÁÆô¼´¿ÉÉúЧ£» £» £» £»£» £»£»£»¸Ã²½Öè½ö¿ÉÓÃÀ´·À»¤Õë¶ÔSMB·þÎñÆ÷£¨SMB SERVER£©µÄ¹¥»÷£¬£¬£¬£¬£¬£¬ÎÞ·¨¶ÔSMB¿Í»§¶Ë£¨SMB Client£©½øÐзÀ»¤¡£¡£ ¡£¡£¡£¡£¡£


2. ÉèÖ÷À»ðǽսÊõ


ÔÚÌìǵ·À»ðǽ×öºÃ°²È«Õ½Êõ×èÖ¹SMBͨѶÁ÷³öÆóÒµÄÚ²¿£¬£¬£¬£¬£¬£¬ÏêÇé¿É²Î¿¼Î¢Èí¹Ù·½µÄÖ¸ÄÏ£ºhttps://support.microsoft.com/zh-cn/help/3185535/preventing-smb-traffic-from-lateral-connections¡£¡£ ¡£¡£¡£¡£¡£


3. ²úÆ··À»¤

Õë¶Ô´Ë·ì϶£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅIDS¡¢IPS¡¢WAF¡¢APT²úÆ·ÒѰ䲼¹æ¶¨Éý¼¶°ü£¬£¬£¬£¬£¬£¬ÏÂÔØµØÖ·£º/article/type/1/140.html¡£¡£ ¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó



https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796